{"id":"T1569.001","name":"Launchctl","url":"https://attack.mitre.org/techniques/T1569/001","tactics":["execution"],"platforms":["macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0265","stix_id":"x-mitre-detection-strategy--77078baf-96f1-413a-bf5b-96b42486e26c","name":"Detection Strategy for System Services: Launchctl","url":"https://attack.mitre.org/detectionstrategies/DET0265","analytics":[{"id":"AN0736","stix_id":"x-mitre-analytic--0297fd45-97bc-4913-8d38-218eae431544","name":"Analytic 0736","description":"Abuse of launchctl to execute or manage Launch Agents and Daemons. Defender perspective: correlation of suspicious plist file creation or modification in LaunchAgents/LaunchDaemons directories with subsequent execution of the launchctl command. Abnormal executable paths (e.g., /tmp, /Shared) or launchctl activity followed by network connections are highly suspicious.","url":"https://attack.mitre.org/detectionstrategies/DET0265#AN0736","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"execution of launchctl load/unload/start commands","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"write of plist files in /Library/LaunchAgents or /Library/LaunchDaemons","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"launchctl spawning new processes","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"creation or loading of new launchd services","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"MonitoredPaths","description":"Paths to monitor for suspicious plist files, such as /Library/LaunchAgents, /Library/LaunchDaemons, ~/Library/LaunchAgents."},{"field":"SuspiciousExecPaths","description":"Uncommon executable paths (e.g., /tmp, /Shared) that should raise alerts when associated with launchctl services."},{"field":"TimeWindow","description":"Correlation window for detecting plist file creation and subsequent launchctl execution."}],"live":true,"detection_strategies":["DET0265"],"techniques":["T1569.001"]}],"live":true,"version":"1.0","techniques":["T1569.001"]}],"sigma_rules":[{"id":"ae9d710f-dcd1-4f75-a0a5-93a73b5dda0e","title":"Launch Agent/Daemon Execution Via Launchctl","author":"Pratinav Chandra","status":"test","level":"medium","date":"2024-05-13","modified":null,"description":"Detects the execution of programs as Launch Agents or Launch Daemons using launchctl on macOS.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1569.001/T1569.001.md","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/","https://www.welivesecurity.com/2020/07/16/mac-cryptocurrency-trading-application-rebranded-bundled-malware/","https://www.trendmicro.com/en_us/research/18/d/new-macos-backdoor-linked-to-oceanlotus-found.html","https://www.loobins.io/binaries/launchctl/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.t1569.001","attack.t1543.001","attack.t1543.004"],"path":"rules/macos/process_creation/proc_creation_macos_launchctl_execution.yml","techniques":["T1569.001","T1543.001","T1543.004"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}